Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 21 Aug 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in Dromara RuoYi-Vue-Plus up to 5.6.2. This issue affects the function FlwInstanceController/FlwDefinitionController/FlwCategoryController/FlwSpelController/TestLeaveController of the component Workflow Endpoint. Such manipulation leads to improper authorization. The attack can be launched remotely. | |
| Title | Dromara RuoYi-Vue-Plus Workflow Endpoint TestLeaveController improper authorization | |
| First Time appeared |
Dromara
Dromara ruoyi-vue-plus |
|
| Weaknesses | CWE-266 CWE-285 |
|
| CPEs | cpe:2.3:a:dromara:ruoyi-vue-plus:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Dromara
Dromara ruoyi-vue-plus |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-21T19:36:40.600Z
Reserved: 2026-08-21T13:14:23.188Z
Link: CVE-2026-77795
No data.
Status : Received
Published: 2026-08-21T19:17:51.393
Modified: 2026-08-21T19:17:51.393
Link: CVE-2026-77795
No data.
OpenCVE Enrichment
No data.